
unicorn
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Hide your Powershell script in plain sight. Bypass all Powershell security features

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

AV/EDR evasion via direct system calls.

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Go shellcode loader that combines multiple evasion techniques

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.

A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.

A simple PoC to invoke an encrypted shellcode by using an hidden call

Adversary Emulation Framework

Shellcode loader demonstrating multiple execution techniques including direct syscalls, IAT evasion, encrypted payloads, PPID spoofing, and code…

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Foxit PDF Reader Remote Code Execution Exploit

WIP shellcode loader in nim with EDR evasion techniques

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…


Google Chrome CVE-2026-6307 PoC